UrlSigningTest.php 7.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221
  1. <?php
  2. namespace Illuminate\Tests\Integration\Routing;
  3. use Illuminate\Contracts\Routing\UrlRoutable;
  4. use Illuminate\Http\Request;
  5. use Illuminate\Routing\Middleware\ValidateSignature;
  6. use Illuminate\Support\Carbon;
  7. use Illuminate\Support\Facades\Route;
  8. use Illuminate\Support\Facades\URL;
  9. use InvalidArgumentException;
  10. use Orchestra\Testbench\TestCase;
  11. class UrlSigningTest extends TestCase
  12. {
  13. public function testSigningUrl()
  14. {
  15. Route::get('/foo/{id}', function (Request $request, $id) {
  16. return $request->hasValidSignature() ? 'valid' : 'invalid';
  17. })->name('foo');
  18. $this->assertIsString($url = URL::signedRoute('foo', ['id' => 1]));
  19. $this->assertSame('valid', $this->get($url)->original);
  20. }
  21. public function testSigningUrlWithCustomRouteSlug()
  22. {
  23. Route::get('/foo/{post:slug}', function (Request $request, $slug) {
  24. return ['slug' => $slug, 'valid' => $request->hasValidSignature() ? 'valid' : 'invalid'];
  25. })->name('foo');
  26. $model = new RoutableInterfaceStub;
  27. $model->routable = 'routable-slug';
  28. $this->assertIsString($url = URL::signedRoute('foo', ['post' => $model]));
  29. $this->assertSame('valid', $this->get($url)->original['valid']);
  30. $this->assertSame('routable-slug', $this->get($url)->original['slug']);
  31. }
  32. public function testTemporarySignedUrls()
  33. {
  34. Route::get('/foo/{id}', function (Request $request, $id) {
  35. return $request->hasValidSignature() ? 'valid' : 'invalid';
  36. })->name('foo');
  37. Carbon::setTestNow(Carbon::create(2018, 1, 1));
  38. $this->assertIsString($url = URL::temporarySignedRoute('foo', now()->addMinutes(5), ['id' => 1]));
  39. $this->assertSame('valid', $this->get($url)->original);
  40. Carbon::setTestNow(Carbon::create(2018, 1, 1)->addMinutes(10));
  41. $this->assertSame('invalid', $this->get($url)->original);
  42. }
  43. public function testTemporarySignedUrlsWithExpiresParameter()
  44. {
  45. $this->expectException(InvalidArgumentException::class);
  46. $this->expectExceptionMessage('reserved');
  47. Route::get('/foo/{id}', function (Request $request, $id) {
  48. return $request->hasValidSignature() ? 'valid' : 'invalid';
  49. })->name('foo');
  50. URL::temporarySignedRoute('foo', now()->addMinutes(5), ['id' => 1, 'expires' => 253402300799]);
  51. }
  52. public function testSignedUrlWithUrlWithoutSignatureParameter()
  53. {
  54. Route::get('/foo/{id}', function (Request $request, $id) {
  55. return $request->hasValidSignature() ? 'valid' : 'invalid';
  56. })->name('foo');
  57. $this->assertSame('invalid', $this->get('/foo/1')->original);
  58. }
  59. public function testSignedUrlWithNullParameter()
  60. {
  61. Route::get('/foo/{id}', function (Request $request, $id) {
  62. return $request->hasValidSignature() ? 'valid' : 'invalid';
  63. })->name('foo');
  64. $this->assertIsString($url = URL::signedRoute('foo', ['id' => 1, 'param']));
  65. $this->assertSame('valid', $this->get($url)->original);
  66. }
  67. public function testSignedUrlWithEmptyStringParameter()
  68. {
  69. Route::get('/foo/{id}', function (Request $request, $id) {
  70. return $request->hasValidSignature() ? 'valid' : 'invalid';
  71. })->name('foo');
  72. $this->assertIsString($url = URL::signedRoute('foo', ['id' => 1, 'param' => '']));
  73. $this->assertSame('valid', $this->get($url)->original);
  74. }
  75. public function testSignedUrlWithMultipleParameters()
  76. {
  77. Route::get('/foo/{id}', function (Request $request, $id) {
  78. return $request->hasValidSignature() ? 'valid' : 'invalid';
  79. })->name('foo');
  80. $this->assertIsString($url = URL::signedRoute('foo', ['id' => 1, 'param1' => 'value1', 'param2' => 'value2']));
  81. $this->assertSame('valid', $this->get($url)->original);
  82. }
  83. public function testSignedUrlWithSignatureTextInKeyOrValue()
  84. {
  85. Route::get('/foo/{id}', function (Request $request, $id) {
  86. return $request->hasValidSignature() ? 'valid' : 'invalid';
  87. })->name('foo');
  88. $this->assertIsString($url = URL::signedRoute('foo', ['id' => 1, 'custom-signature' => 'signature=value']));
  89. $this->assertSame('valid', $this->get($url)->original);
  90. }
  91. public function testSignedUrlWithAppendedNullParameterInvalid()
  92. {
  93. Route::get('/foo/{id}', function (Request $request, $id) {
  94. return $request->hasValidSignature() ? 'valid' : 'invalid';
  95. })->name('foo');
  96. $this->assertIsString($url = URL::signedRoute('foo', ['id' => 1]));
  97. $this->assertSame('invalid', $this->get($url.'&appended')->original);
  98. }
  99. public function testSignedUrlParametersParsedCorrectly()
  100. {
  101. Route::get('/foo/{id}', function (Request $request, $id) {
  102. return $request->hasValidSignature()
  103. && intval($id) === 1
  104. && $request->has('paramEmpty')
  105. && $request->has('paramEmptyString')
  106. && $request->query('paramWithValue') === 'value'
  107. ? 'valid'
  108. : 'invalid';
  109. })->name('foo');
  110. $this->assertIsString($url = URL::signedRoute('foo', ['id' => 1,
  111. 'paramEmpty',
  112. 'paramEmptyString' => '',
  113. 'paramWithValue' => 'value',
  114. ]));
  115. $this->assertSame('valid', $this->get($url)->original);
  116. }
  117. public function testSignedMiddleware()
  118. {
  119. Route::get('/foo/{id}', function (Request $request, $id) {
  120. return $request->hasValidSignature() ? 'valid' : 'invalid';
  121. })->name('foo')->middleware(ValidateSignature::class);
  122. Carbon::setTestNow(Carbon::create(2018, 1, 1));
  123. $this->assertIsString($url = URL::temporarySignedRoute('foo', now()->addMinutes(5), ['id' => 1]));
  124. $this->assertSame('valid', $this->get($url)->original);
  125. }
  126. public function testSignedMiddlewareWithInvalidUrl()
  127. {
  128. Route::get('/foo/{id}', function (Request $request, $id) {
  129. return $request->hasValidSignature() ? 'valid' : 'invalid';
  130. })->name('foo')->middleware(ValidateSignature::class);
  131. Carbon::setTestNow(Carbon::create(2018, 1, 1));
  132. $this->assertIsString($url = URL::temporarySignedRoute('foo', now()->addMinutes(5), ['id' => 1]));
  133. Carbon::setTestNow(Carbon::create(2018, 1, 1)->addMinutes(10));
  134. $response = $this->get($url);
  135. $response->assertStatus(403);
  136. }
  137. public function testSignedMiddlewareWithRoutableParameter()
  138. {
  139. $model = new RoutableInterfaceStub;
  140. $model->routable = 'routable';
  141. Route::get('/foo/{bar}', function (Request $request, $routable) {
  142. return $request->hasValidSignature() ? $routable : 'invalid';
  143. })->name('foo');
  144. $this->assertIsString($url = URL::signedRoute('foo', $model));
  145. $this->assertSame('routable', $this->get($url)->original);
  146. }
  147. public function testSignedMiddlewareWithRelativePath()
  148. {
  149. Route::get('/foo/relative', function (Request $request) {
  150. return $request->hasValidSignature($absolute = false) ? 'valid' : 'invalid';
  151. })->name('foo')->middleware('signed:relative');
  152. $this->assertIsString($url = 'https://fake.test'.URL::signedRoute('foo', [], null, $absolute = false));
  153. $this->assertSame('valid', $this->get($url)->original);
  154. $response = $this->get('/foo/relative');
  155. $response->assertStatus(403);
  156. }
  157. }
  158. class RoutableInterfaceStub implements UrlRoutable
  159. {
  160. public $key;
  161. public $slug = 'routable-slug';
  162. public function getRouteKey()
  163. {
  164. return $this->{$this->getRouteKeyName()};
  165. }
  166. public function getRouteKeyName()
  167. {
  168. return 'routable';
  169. }
  170. public function resolveRouteBinding($routeKey, $field = null)
  171. {
  172. //
  173. }
  174. public function resolveChildRouteBinding($childType, $routeKey, $field = null)
  175. {
  176. //
  177. }
  178. }